Cookies Policy
Last updated 5 August 2026
This page names every cookie hudr.net sets, everything the site keeps in your browser’s own storage, and the outside companies that see your IP address because your browser has to fetch something from them. It is a list, not a disclaimer — if something is not on it, we are not doing it.
1. The short version
- Seven cookies, all ours. Four of them sign you in and protect what you do; three remember a setting you chose. The full list is in section 2, with how long each one lasts.
- No tracking of any kind. We run no analytics product, no advertising network, no tracking pixel and no session recorder. Nothing of that kind exists anywhere in the site’s code.
- Two outside companies still see you, without setting a cookie: Google, because every page loads its fonts, and Giphy, because GIFs load from Giphy’s own servers. “No third-party cookies” is not the same as “no third party sees you”, so we spell out the difference in section 4.
- Ads on hudr.net are our own. They are served from hudr.net and counted on our servers. No ad network is involved and no ad puts anything in your browser.
This page is about the identifiers themselves. What we do with the data behind them — what gets logged, for how long, and what happens when you delete your account — is in the Privacy Policy. Deleting your account signs you out on every device and stops your profile and your content being visible to anyone on hudr.net; it is not a wipe of our database, and the Privacy Policy lists what is kept afterwards.
2. Cookies we set
All of these are first-party: they belong to hudr.net, they are sent only to hudr.net, and no other
website can read them. Most are encrypted before they leave our server, so their contents are
meaningless to anything else on your device. All of them are set with SameSite=lax —
in plain English, your browser will generally not send them to us when the request comes from a page
on somebody else’s website.
The first three are set for signed-out visitors too, including on this page. That is not tracking — the site needs a session and a form token before you have an account, in order to run a sign-up form at all.
hudrnet_session— your session. It links this browser to your signed-in account and carries short-lived things like the language you picked or the error message from the form you just submitted. Encrypted, and flaggedHttpOnlyso page scripts cannot read it. Without this you cannot be signed in. Lasts 365 days, renewed each time you visit.XSRF-TOKEN— anti-forgery token. Anything that changes something — posting, messaging, applying for a job, paying out a wallet balance — has to send this value back, which proves the request came from a hudr.net page rather than from another site that happened to catch you signed in. It is deliberately readable by the page’s own scripts; that is how it gets sent back. Lasts 365 days.device_id— one browser told apart from another. A random identifier (a UUID) handed to your browser the first time it arrives. Encrypted andHttpOnly. It is not used to count views on posts or reels — those are counted server-side, precisely so that a value the browser controls cannot be replayed to inflate them. Lasts 365 days.remember_web_…— keeps you signed in after you close the browser. Set only when “Remember me” is ticked on the sign-in form, which it is by default — untick it and this cookie is never created. The full name ends in a fixed 40-character hash. Lasts 400 days, or until you sign out.theme— light or dark. Written when you change the theme. If you are signed in, the same choice is also saved on your account, so it follows you to your other devices. Lasts 3 years.selected_locale— your interface language. Only written when you change it. Lasts until you clear it.device_type— desktop or mobile layout. Only written if you use the layout switcher; most people never have this cookie. Lasts until you clear it.
That is the complete list. There is no eighth cookie, and nothing on hudr.net writes a cookie from
JavaScript — the page scripts only ever read XSRF-TOKEN, to send it back with
your next action.
3. What we keep in your browser’s storage
Some settings are kept in your browser’s local storage rather than in a cookie. The difference matters: local storage is not attached to your requests, so unlike a cookie these values are never sent to our servers as you browse. They sit on that one device until you clear the site’s data, and they are per-device — changing them on your phone does not change them on your laptop.
hudr-demo-theme— light or dark on the main site. If the key is absent the site follows your operating system; that is exactly what the “System” option does — it deletes the key rather than storing a third value.theme— the same light/dark choice on the older app screens.hudr-admin-theme— light or dark inside the admin area. Only ever written for staff accounts.notificationsSound— whether the notification sound is on. Only the literal value1means on; switching it off deletes the key.videoPlayerMuted— whether videos start muted.reelsMuted,reelsVolume— mute state and volume in reels. Reels start muted, because browsers only allow autoplay when there is no sound.stories_videos_muted— mute state for videos in stories.hide_wallet_balance— whether your wallet balance is hidden on screen, so the number is not visible to someone standing behind you.FUSED_EMOJIS,FUSED_REACTIONS— the emoji and reactions you have used recently, so the picker can offer them first. Kept on the device; not sent to us.
We do not use session storage, and we do not use any of the harder-to-clear techniques people worry about: no Flash storage, no IndexedDB identifiers, no canvas or audio fingerprinting in the browser, no ETag or cache tricks used as an identifier.
4. Third parties your browser contacts
None of these set a cookie on hudr.net. They still receive your IP address, because your browser has to ask them for a file, and an IP address is how any file gets delivered. We would rather say that plainly than hide behind “we set no third-party cookies”.
- Google Fonts — every hudr.net page loads the Inter typeface from
fonts.googleapis.comandfonts.gstatic.com. That includes this page, pages you can see while signed out, and a hudr.net post embedded on somebody else’s website. Those requests set no cookie, but they tell Google your IP address, your browser’s User-Agent string, and which page asked for the font. In short: Google sees the IP address of every visitor. If you block those two domains, hudr.net still works — the text falls back to your system’s own typeface. - Giphy — GIFs are not copied onto our servers. A GIF in a post or a message is
stored as a link to
media2.giphy.com, and your browser fetches the image straight from Giphy. So Giphy sees the IP address of everyone who views a GIF, and which GIF it was — including inside a private direct message. Searching for a GIF works the other way round: the search runs from our server, so the words you type reach Giphy from us, not from your browser. - Amazon S3 — photos, videos and voice notes are stored on Amazon S3 and are loaded by your browser from Amazon’s servers, so Amazon sees the IP address of whoever loads a piece of media. No cookie is involved.
- Google sign-in — only if you choose it. Signing in with Google sends you to Google, where Google’s own cookies and policies apply, and sends us back the account details you approve. If you sign in with an email address and a password, this never happens.
5. Services that never touch your browser
For completeness, because people reasonably ask: these companies handle hudr.net data but are contacted by our servers, not by your browser. They set nothing on your device and see nothing about your browsing.
- Amazon SNS — sends the six-digit code when you verify a phone number.
- Our email provider (ElasticEmail, over SMTP) — sends every email we send you, from sign-up codes to notification digests.
- ipinfo.io — our server asks it to turn an IP address into an approximate country, region, city, timezone and network, for the security log that lets you see where your account has been used. The lookup is made by us; your browser never contacts ipinfo.io. What that log holds, and the 30 days it is kept for, is described in the Privacy Policy.
6. Embeds on other people’s websites
Two hudr.net things are designed to run inside a website that is not ours, so it is worth being exact about what they do to a visitor who may never have heard of us.
- A post embed — an iframe showing one hudr.net post. We strip
Set-Cookiefrom that response entirely, so viewing an embedded post sets no hudr.net cookie at all, not even a session. It does load the Inter font from Google, exactly as described in section 4. - The reviews widget a business can put on its own site. It sets no cookies, loads no fonts, and pulls in no external assets of any kind — that exemption is deliberate. The one network request any version of it makes is a single avatar image, served from hudr.net.
Neither embed reads who you are. They never look at the session, they render the same thing for every visitor, and nothing about viewing one is recorded against your account — that is deliberate, so that a site hosting an embed cannot use it to learn about its own readers.
7. What we don’t do
- No analytics product. No Google Analytics, no Tag Manager, no Meta pixel, no session recorder, no A/B testing SDK. None of these appear anywhere in the site’s code.
- No advertising cookies and no ad network. Advertising on hudr.net is our own inventory: the ad is served from hudr.net and its impressions and clicks are counted on our servers. Nothing is placed in your browser, and no outside advertiser receives your data to target you elsewhere.
- No cross-site tracking. We do not set cookies on other people’s sites, we do not buy or read identifiers from anyone who does, and our cookies cannot be read from another domain.
- No cookie banner — because there is no tracking to ask you about. The first four cookies in section 2 are what makes signing in work; the last three only hold a setting you chose yourself.
One thing we would rather disclose than leave for you to discover: hudr.net’s admin panel has a setting that can inject custom code into every page’s head or footer. It ships empty and switched off, and nothing is in it. If it is ever used for something that sets a cookie or contacts a third party, this page is updated in the same change.
8. How to control this
- Your browser. Every modern browser lets you inspect, delete and block cookies for one site. Chrome, Edge, Firefox and Safari all have this under privacy or site settings.
- Blocking the essential ones has a cost. If
hudrnet_sessionorXSRF-TOKENis blocked you cannot sign in, post, or send a message. There is no version of the site that works without them. - Clearing site data resets your theme, notification sound, mute settings, hidden wallet balance and recent emoji, and signs you out of that browser.
- Signing out ends the session on our side and clears the remember-me cookie for that browser. Your Settings page also lists the devices where you are signed in and lets you end those sessions.
- Blocking Google or Giphy at the browser or extension level is fine by us. The site works without Google’s fonts; GIFs simply will not display.
- A private window throws away everything on this page when you close it.
9. Changes, and how to reach us
We update this page whenever a cookie, a storage key or a third-party asset is added or removed, and change the date at the top when we do. There is no separate archive; the version you are reading is the current one.
hudr.net is operated by Hudr.net. If something here is unclear, or you think the site set something that is not on this list, tell us through the contact page or by email: [email protected] . A specific report (“this cookie appeared on this page”) is genuinely useful — this list is meant to be checkable.
For what happens to your data once it reaches us, read the Privacy Policy; for the rules of using hudr.net, the Terms of Use. Answers to common questions are on the FAQ and in the Help Centre.